Denial of Service Vulnerability in gpsd Affecting GPS Data Interpretation
CVE-2013-2038

Currently unrated

Key Information:

Vendor
CVE Published:
6 February 2014

What is CVE-2013-2038?

The NMEA0183 driver in gpsd versions before 3.9 is susceptible to a vulnerability that allows remote attackers to trigger denial of service by sending a specially crafted GPS packet. This malformed packet can cause the gpsd daemon to terminate unexpectedly, potentially leading to service disruptions. Attackers can exploit this flaw via a malformed $GPGGA interpreted sentence that omits specific fields and a terminator, which may further expose systems to arbitrary code execution risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.